Overview of the October 2007 Microsoft patches and their status.
| # | Affected | Contra Indications | Known Exploits | Microsoft rating | ISC rating(*) | |
|---|---|---|---|---|---|---|
| clients | servers | |||||
| MS07-055 | An input validation failure allows remote code execution. | |||||
| Windows - Kodak image viewer CVE-2007-2217 |
KB 923810 |
No publicly known exploits | Critical | Critical | Important | |
| MS07-056 | Input validation failure in the NNTP protocol allows remote code execution. Updates MS06-076. |
|||||
| Outlook express and Windows mail (vista) CVE-2007-3897 |
KB 941202 | No publicly known exploits | Critical | Critical | Important | |
| MS07-057 | Memory corruption in Internet Explorer lead to remote code execution. Multiple address bar spoofing vulnerabilities. Cumulative patch for IE, replaces MS07-045. |
|||||
| MSIE CVE-2007-3893 CVE-2007-3892 CVE-2007-1091 CVE-2007-3826 |
KB 939653 | Some vulnerabilities have been publicly known since February 22nd 2007. | Critical | Critical | Important | |
| MS07-058 | NTLMSSP authentication can be abused to cause the RPC service to stop in a way that it also prevent the system from restarting the service. Replaces MS06-031 (information leak). |
|||||
| Windows RPC CVE-2007-2228 |
KB 933729 | No publicly known exploits | Important | Important | Important | |
| MS07-059 | XSS issues on the sharepoint server cause elevate privileges problems on the server itself and information leaks on the client connecting to such server. | |||||
| Sharepoint CVE-2007-2581 |
Publicly known exploit since May 4th 2007. | Important | Less urgent(**) | Important(**) | ||
| MS07-060 | Input validation problem allows remote code execution with the rights of the logged on user. | |||||
| Word CVE-2007-3899 |
KB 942695 | Abused in targeted exploits | Critical | Critical | Important | |
(**): Typical for XSS issues: it's mostly important for the client, but the actual problem is on the server. The risk is mainly linked to the data to be protected and it can vary wildly depending on the organization and its needs.
--
Swa Frantzen -- NET2S
Login here to post a comment. Diary Archive